CVE-2019-12269

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/05/2019
Last modified:
07/11/2023

Description

Enigmail before 2.0.11 allows PGP signature spoofing: for an inline PGP message, an attacker can cause the product to display a "correctly signed" message indication, but display different unauthenticated text.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:enigmail:enigmail:*:*:*:*:*:*:*:* 2.0.11 (excluding)